INVERSE-CLOSED ADDITIVE SUBGROUPS OF FIELDS 
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Abstract. We describe the additive subgroups of fields which are closed 
with respect to taking inverses. In particular, in characteristic different 
from two any such subgroup is either a subfield or the kernel of the trace 
map of a quadratic subextension of the field. 



1. Introduction 

The following result of Hua, as stated in |Art571 Theorem 1.15], plays 
a role in connection with the fundamental theorem of projective geometry 
(see |Art571 Chapter II, Sections 9 and 10]): an additive map between divi- 
sion rings sending 1 to 1 and inverse elements to inverse elements is either 
an isomorphism or an antiisomorphism of rings. The first step in the proof 
is showing that the map preserves the operation (a, b) i— » aba. This follows 
from Hua's identity (first mentioned in Hua49b , but see I.Tac68| page 2] 
or |.Iac74| page 89] for the more manageable form given here) 

(1) a - (a' 1 + {b- 1 - a)' 1 )- 1 = aba, 

which holds in any associative ring provided all inverses involved are defined, 
that is, provided a, b and ab — 1 are invertible. The rest of the proof (orig- 
inally given in Hua49a ) does not use that the map preserves inverses, but 
rather the product aba. This part of the proof has been later generalized 
in a number of directions, notably to arbitrary domains by Jacobson and 
Rickart, see the references given in |.Tac68| page 3]. 

A problem of a similar flavour as Hua's result, but which seems not to 
have received attention, is a description of the additive subgroups of division 
rings which contain the inverses of their nonzero elements. In the present 
note we fill this gap in the commutative case. 

For any subset S of a field E we write 5 _1 = {s _1 | ^ s € E}. We call 
S inverse- closed if C S. We prove the following results. 

Theorem 1. Let E be a field of characteristic different from two and let 
A be a non-trivial inverse- closed additive subgroup of E. Then A is either 
a subfield of E or the set of elements of trace zero in some quadratic field 
extension contained in E. 

Conversely, it is plain that the set of elements of trace zero in any qua- 
dratic field extension contained in E is inverse-closed. 
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Theorem 2. Let E be a field of characteristic two and let A be an inverse- 
closed additive subgroup of E. Then A is an F 2 -subspace of F for some 
subfield F of E. 

Conversely, any i ?2 -subspace of a subfield F of characteristic two is clearly 
inverse-closed. 

Because of the method of proof employed, based in particular on Hua's 
identity, it is natural to ask for extensions of Theorems ^ and [2] to division 
algebras. However, the correct extension is not yet clear to this author from 
a variety of examples found. 

The inversion map in finite fields is of cryptographic interest. For ex- 
ample, inversion in the finite field of 2 8 elements is the nonlinear trans- 
formation employed in the S-boxes in the Advanced Encryption Standard 
(Rijndael) jFIPOlj . In view of possible applications, as in CDVSVj.the spe- 
cial case of Theorems ^and[5] where E is a finite field deserves the following 
separate mention. 

Theorem 3. Let E be a finite field and let A be a non-trivial inverse-closed 
additive subgroup of E. Then A is either a subfield of E or the set of 
elements of trace zero in some quadratic field extension contained in E. 

Note that when E has characteristic two the two alternatives in the con- 
clusion coincide. The finiteness assumption on E allows various proofs of 
Theorem El which differ from that of the general case. For example, one of 
the advantages of finite fields is that an arbitrary subset can be described by 
the unique monic polynomial which has the elements of the subset as sim- 
ple roots. Algebraic properties of the subset often translate into properties 
of the corresponding polynomial. In particular, here we record a proof of 
Theorem 01 based on p-polynomials. 

I am grateful to A. Caranti for asking the question answered in Theorem^] 

2. Proofs 

Note that an inverse-closed additive subgroup A of E is necessarily a 
subspace of E over its prime field. This is clear if E has positive charac- 
teristic. If E has characteristic zero, then A is a Q-subspace of E, because 
(mn~ 1 )a = m(na -1 ) -1 G A for a £ A* and m,n integers with n^O. 

Lemma 4. Let A be an inverse-closed additive subgroup of E. Then a 2 b G A 
for all a,b £ A. Furthermore, if E has characteristic different from two, then 
abc G A for all a,b,c £ A. 

Proof. Hua's identity Q implies that aba = a 2 b G A for all a, b G A, the 
degenerate cases where one or more of a, b and ab — 1 vanish being obvious. 
The second assertion follows from the identity 2abc = (a+c) 2 b—a 2 b—c 2 b. □ 

It follows at once by taking c = 1 in Lemma|IJ that the only inverse-closed 
additive subgroups containing 1 of a field E of characteristic not two are the 
subfields of E. According to Theorem |2 this assertion does not extend to 
arbitrary fields of characteristic two. 

Proof of Theorem^ The inverse-closed subset K = {ab \ a, b G ^4} of E is 
a subring, and hence a subfield, because ab — cd = a(b — a _1 c<i) G K and 
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(ab)(cd) = (abc)d £ K for all a,b,c,d £ A with a / 0. Choose a nonzero 
element a £ A. Then Aa -1 C X, and Fa C ^4 because of the second 
assertion of Lemma HJ Hence ^4 = Fa, with a 2 G if. We conclude that 
either A coincides with the subfield K of E, or is the set of elements of trace 
zero in the quadratic field extension K(a) = K + Ka of E. □ 

The following example shows that the subset {ab \ a, b £ A} of £7, which 
we have used in the proof of Theorem ^ need not be a subfield when E 
has characteristic two. Let E = F2(ui, u 2 , u^, 114) be a purely transcendental 
extension of transcendence degree four of the field of two elements F2, and let 
A = E 2 u x + E 2 u 2 + E 2 u 3 + E 2 Ui . Then {ab | a, b £ A} = E 2 + ^ 4<j E 2 u i u j 
is a vector space over E 2 of dimension 7, and hence not a subfield of E. 

Proof of Theorem^ Let R be the subring generated by the squares of the 
elements of A, and let K be the subfield of E generated by R. The first 
assertion of Lemma |1] shows inductively that A is an i?-submodule of E. 
Since ar^ 1 = (a _1 r) _1 £ A ioi a £ A and r £ R we conclude that ^4 is 
a /T-subspace of E. Finally, if F is the subfield of E generated by A then 
K = F 2 and A C F, as desired. □ 

We conclude by giving a proof of Theorem 01 based on p-polynomials. 
A ^-polynomial, over a field of positive characteristic p, is a polynomial all 
whose monomials have exponents equal to powers of p. A basic property of p- 
polynomials is that their sets of roots in any field are additive subgroups. We 
refer to Chapter 3 of jLN83j for an extensive discussion of p-polynomials. We 
also need the concept of self-reciprocal polynomial. For a polynomial f(x) = 
YH=Q a i x% w hh aoa n / we define its reciprocal polynomial as x n f(l/x) = 
Y^i=o a n-i% 1 - The roots of the reciprocal polynomial are clearly the inverses 
of the roots of the original polynomial, with corresponding multiplicities. 
We call self-reciprocal a polynomial f(x) = Y17=o aixl i w ith aoa n 7^ 0, which 
equals its reciprocal polynomial up to a scalar factor. This clearly implies 
that a n = ±ao- For a polynomial with nonzero constant term and with 
distinct roots, being self-reciprocal is equivalent to its set of roots being 
inverse-closed. 

Proof of Theorem^ Let E have order p-f . Then E is the splitting field 
over F p of the polynomial x p — x. According to Theorems 3.50 and 3.52 
of |LN83j . the additive subgroups A of E, that is, its F p -subspaces, are in a 
bijection with the monic divisors /a(^) of x' p — x which are p-polynomials, 
given by letting such a polynomial correspond to the set A of its roots. An 
additive subgroup A of E is inverse-closed if and only if fA(x)/x is self- 
reciprocal. Since /a(^) is a p-polynomial, degree reasons easily imply that 
it is a binomial, and hence has the form x p — x or x v + x, for some r. In 
the former case A is the subfield of E of order p r . In the latter case we may 
assume that E has characteristic different from two, and hence A is not a 
subfield. Then the roots in E of the polynomial x' p — x, which include 1, 
form a subfield of E, of order a divisor of p 2r larger than \A\ = p r . Hence 
the roots of the polynomial form a subfield of E of order p 2r . The roots of 
x p + x form the kernel of the trace map of this subfield over its subfield of 
order p r . □ 
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